<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:admin="http://webns.net/mvcb/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">
<channel>
    <title>Niels Provos</title>
    <link>http://www.provos.org/</link>
    <description>systrace, spybye and other things.</description>
    <dc:language>en</dc:language>
    <generator>Serendipity 1.3.1 - http://www.s9y.org/</generator>
    
    

<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feeds.feedburner.com/NielsProvos" type="application/rss+xml" /><feedburner:emailServiceId>NielsProvos</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com" /><item>
    <title>San Mai Knife</title>
    <link>http://feedproxy.google.com/~r/NielsProvos/~3/1T_fTbvGnpA/index.php</link>
            <category>Hacking</category>
    
    <comments>http://www.provos.org/index.php?/archives/76-San-Mai-Knife.html#comments</comments>
    <wfw:comment>http://www.provos.org/wfwcomment.php?cid=76</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.provos.org/rss.php?version=2.0&amp;type=comments&amp;cid=76</wfw:commentRss>
    

    <author>nospam@example.com (Niels Provos)</author>
    <content:encoded><![CDATA[
    <a href="http://www.flickr.com/photos/nielsprovos/4013107612/" title="Failed San Mai Attempt by provos@monkey, on Flickr"><img src="http://farm3.static.flickr.com/2611/4013107612_a6135c6575_m.jpg" width="240" height="159" alt="Failed San Mai Attempt" class="serendipity_image_left" style="border: 0px none ; float: left; padding-left: 5px; padding-right: 5px;" /></a> A while ago, I forged a <a href="http://www.flickr.com/photos/nielsprovos/3601778013/">San Mai billet</a> with the hope to turn it into a tanto.  Unfortunately, the forge I was using had a very oxygen rich atmosphere and the welds did not take very well.   Over the last couple of days, I spent some time grinding and heat treating the remaining steel into a knife for practice purposes.   The cable structure of the knife came out very nicely with repeated applications of lemon juice and metal polish to remove the oxides left by the lemon juice etch.<br />
<br />
I also figured out how to take decent pictures of the steel.   The trick was to use direct light rather than diffused light that shines directly on the blade, and then have black surfaces inside the light box.  The angle of the knife needs to be so that the black is reflected do the camera.   Although, this is a failed knife due to all the welding flaws, it still was an interesting experiment. 
    <div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/NielsProvos?a=1T_fTbvGnpA:XgZ60SrDLP8:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/NielsProvos?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/NielsProvos?a=1T_fTbvGnpA:XgZ60SrDLP8:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/NielsProvos?i=1T_fTbvGnpA:XgZ60SrDLP8:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/NielsProvos?a=1T_fTbvGnpA:XgZ60SrDLP8:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/NielsProvos?i=1T_fTbvGnpA:XgZ60SrDLP8:F7zBnMyn0Lo" border="0"></img></a>
</div>]]></content:encoded>

    <pubDate>Thu, 15 Oct 2009 14:48:38 -0700</pubDate>
    <guid isPermaLink="false">http://www.provos.org/index.php?/archives/76-guid.html</guid>
    <category>bladesmithing</category>

<feedburner:origLink>http://www.provos.org/index.php?/archives/76-San-Mai-Knife.html</feedburner:origLink></item>
<item>
    <title>Forging a Wakizashi</title>
    <link>http://feedproxy.google.com/~r/NielsProvos/~3/QWkJloY3HYo/index.php</link>
            <category>Hacking</category>
    
    <comments>http://www.provos.org/index.php?/archives/75-Forging-a-Wakizashi.html#comments</comments>
    <wfw:comment>http://www.provos.org/wfwcomment.php?cid=75</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.provos.org/rss.php?version=2.0&amp;type=comments&amp;cid=75</wfw:commentRss>
    

    <author>nospam@example.com (Niels Provos)</author>
    <content:encoded><![CDATA[
    <a href="http://www.flickr.com/photos/nielsprovos/3913846940/" title="Wakizashi by provos@monkey, on Flickr"><img src="http://farm4.static.flickr.com/3481/3913846940_26cc91d776_m.jpg" width="240" height="208" alt="Wakizashi" class="serendipity_image_left" style="border: 0px none ; float: left; padding-left: 5px; padding-right: 5px;" /></a>I just finished taking the <a href="http://www.tomboyama.com/">5-day basic forging class</a> taught by Michael Bell at <a href="http://www.dragonflyforge.com/">Dragonfly Forge</a>.   The wakizashi in the picture is the result of it.   The blade is about 18in long and was forged from forge-welded cable.    The forge welding of the cable conducted by Michael and his son Gabriel took the better half of the first day.  Afterward, the steel was forged into a sunobe which has the basic taper for the tang and point of the sword.   We then forged in the ji and the shinogi ji.   The remainder of the time was spent grinding in preparation for heat treatment.   Before the clay was applied, we draw filed the blade so that all file marks were parallel with the edge rather than the perpendicular marks left by the belt grinder.   Applying the clay was a three step process; a light coating of the whole blade, applying the ashi lines, and then coating everything that should remain soft.   You can see the ashi and where the clay was applied on the middle picture.   After heat treating, the blade took on a nice curve and it was back to the grinder.  During the last day there was a little bit of time to polish on stones which showed hints of some very wild hamon as well as some mune yaki.  The whole class was a great experience. 
    <div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/NielsProvos?a=QWkJloY3HYo:UK6SKVCerS4:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/NielsProvos?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/NielsProvos?a=QWkJloY3HYo:UK6SKVCerS4:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/NielsProvos?i=QWkJloY3HYo:UK6SKVCerS4:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/NielsProvos?a=QWkJloY3HYo:UK6SKVCerS4:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/NielsProvos?i=QWkJloY3HYo:UK6SKVCerS4:F7zBnMyn0Lo" border="0"></img></a>
</div>]]></content:encoded>

    <pubDate>Mon, 14 Sep 2009 11:43:26 -0700</pubDate>
    <guid isPermaLink="false">http://www.provos.org/index.php?/archives/75-guid.html</guid>
    <category>bladesmithing</category>
<category>forge</category>
<category>wakizashi</category>

<feedburner:origLink>http://www.provos.org/index.php?/archives/75-Forging-a-Wakizashi.html</feedburner:origLink></item>
<item>
    <title>LEET '10 Call for Papers</title>
    <link>http://feedproxy.google.com/~r/NielsProvos/~3/GkVitRgagUw/index.php</link>
            <category>Malware</category>
            <category>News</category>
            <category>Security</category>
    
    <comments>http://www.provos.org/index.php?/archives/74-LEET-10-Call-for-Papers.html#comments</comments>
    <wfw:comment>http://www.provos.org/wfwcomment.php?cid=74</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.provos.org/rss.php?version=2.0&amp;type=comments&amp;cid=74</wfw:commentRss>
    

    <author>nospam@example.com (Niels Provos)</author>
    <content:encoded><![CDATA[
    The call for papers for the <strong>3rd USENIX Workshop on Large-Scale Exploits and Emergent Threats</strong> (LEET '10) Botnets, Spyware, Worms, and More just went out.   It will be held on <strong>April 27, 2010</strong> in San Jose, CA.<br />
<br />
<a href="http://www.usenix.org/event/leet10/cfp/">LEET '10</a> will be co-located with the 7th USENIX Symposium on Networked Systems Design and Implementation (NSDI '10), which will take place April 28–30, 2010.<br />
<br />
<strong>Important Dates</strong><br />
<ul><li>Submissions due: Thursday, February 25, 2010, 11:59 p.m. PST</li><li>Notification of acceptance: Wednesday, March 24, 2010</li><li>Final papers due: Monday, April 5, 2010</li></ul><br />
<strong>Workshop Organizers</strong><br />
<em>Program Chair</em><ul><li>Michael Bailey, University of Michigan</li></ul><em>Program Committee</em><ul><li>Dan Boneh, Stanford University</li><li>Nick Feamster, Georgia Institute of Technology</li><li>Jaeyeon Jung, Intel Labs, Seattle</li><li>Christian Kreibich, International Computer Science Institute</li><li>Patrick McDaniel, Pennsylvania State University</li><li>Fabian Monrose, University of North Carolina, Chapel Hill</li><li>Jose Nazario, Arbor Networks, Inc.</li><li>Stefan Savage, University of California, San Diego</li><li>Matt Williamson, AVG Technologies</li><li>Yinglian Xie, Microsoft Research</li><li>Vinod Yegneswaran, SRI International</li><br />
</ul>Go submit your work! 
    <div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/NielsProvos?a=GkVitRgagUw:9D9FY1Eoig4:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/NielsProvos?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/NielsProvos?a=GkVitRgagUw:9D9FY1Eoig4:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/NielsProvos?i=GkVitRgagUw:9D9FY1Eoig4:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/NielsProvos?a=GkVitRgagUw:9D9FY1Eoig4:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/NielsProvos?i=GkVitRgagUw:9D9FY1Eoig4:F7zBnMyn0Lo" border="0"></img></a>
</div>]]></content:encoded>

    <pubDate>Sat, 29 Aug 2009 12:35:46 -0700</pubDate>
    <guid isPermaLink="false">http://www.provos.org/index.php?/archives/74-guid.html</guid>
    <category>cfp</category>
<category>malware</category>
<category>research</category>
<category>security</category>

<feedburner:origLink>http://www.provos.org/index.php?/archives/74-LEET-10-Call-for-Papers.html</feedburner:origLink></item>
<item>
    <title>Ask Google's Anti-Malware Team</title>
    <link>http://feedproxy.google.com/~r/NielsProvos/~3/11g6uY9kuM8/index.php</link>
            <category>Malware</category>
            <category>News</category>
            <category>SpyBye</category>
    
    <comments>http://www.provos.org/index.php?/archives/73-Ask-Googles-Anti-Malware-Team.html#comments</comments>
    <wfw:comment>http://www.provos.org/wfwcomment.php?cid=73</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.provos.org/rss.php?version=2.0&amp;type=comments&amp;cid=73</wfw:commentRss>
    

    <author>nospam@example.com (Niels Provos)</author>
    <content:encoded><![CDATA[
    Google's Anti-Malware team has prepared a moderator page where web masters and users <a href="http://moderator.appspot.com/#15/e=a77ea&t=a9521">can ask questions</a> and vote which questions they would like to see answered.   The voting period ends on Friday, August 28th at which point the Anti-Malware team will prepare answers for some of the top-rated questions. 
    <div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/NielsProvos?a=11g6uY9kuM8:nW33ldRMq7Q:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/NielsProvos?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/NielsProvos?a=11g6uY9kuM8:nW33ldRMq7Q:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/NielsProvos?i=11g6uY9kuM8:nW33ldRMq7Q:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/NielsProvos?a=11g6uY9kuM8:nW33ldRMq7Q:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/NielsProvos?i=11g6uY9kuM8:nW33ldRMq7Q:F7zBnMyn0Lo" border="0"></img></a>
</div>]]></content:encoded>

    <pubDate>Sun, 16 Aug 2009 16:42:12 -0700</pubDate>
    <guid isPermaLink="false">http://www.provos.org/index.php?/archives/73-guid.html</guid>
    <category>malware</category>

<feedburner:origLink>http://www.provos.org/index.php?/archives/73-Ask-Googles-Anti-Malware-Team.html</feedburner:origLink></item>
<item>
    <title>New Libevent Releases</title>
    <link>http://feedproxy.google.com/~r/NielsProvos/~3/zja-1LvBcuI/index.php</link>
            <category>Libevent</category>
            <category>News</category>
    
    <comments>http://www.provos.org/index.php?/archives/72-New-Libevent-Releases.html#comments</comments>
    <wfw:comment>http://www.provos.org/wfwcomment.php?cid=72</wfw:comment>

    <slash:comments>1</slash:comments>
    <wfw:commentRss>http://www.provos.org/rss.php?version=2.0&amp;type=comments&amp;cid=72</wfw:commentRss>
    

    <author>nospam@example.com (Niels Provos)</author>
    <content:encoded><![CDATA[
    Nick just announced two new libevent releases.  Here is his summary.<br />
<br />
<strong>Libevent 1.4.12-stable:</strong><br />
You can find the source in the usual place:<br />
<br />
   <a href="http://monkey.org/~provos/libevent-1.4.12-stable.tar.gz">http://monkey.org/~provos/libevent-1.4.12-stable.tar.gz</a><br />
<br />
This is a bugfix-only release, and some of the bugs were kind of nasty.  I'd recommend that you upgrade, especially if you are writing code that uses epoll or evdns.<br />
<br />
Changes in 1.4.12-stable:<br />
<ul><li>Try to contain degree of failure when running on a win32 version so heavily firewalled that we can't fake a socketpair.</li><li>Fix an obscure timing-dependent, allocator-dependent crash in the evdns code.</li><li>Use <u>_VA_ARGS_</u> syntax for varargs macros in event_rpcgen when compiler is not GCC.</li><li>Activate fd events in a pseudorandom order with O(N) backends, so that we don't systematically favor low fds (select) or earlier-added fds (poll, win32).</li><li>Fix another pair of fencepost bugs in epoll.c.  [Patch from Adam Langley.]</li><li>Do not break evdns connections to nameservers when our IP changes.</li><li>Set truncated flag correctly in evdns server replies.</li><li>Disable strict aliasing with GCC: our code is not compliant with it.</li></ul><br />
<strong>Libevent-2.0.2-alpha:</strong><br />
The first alpha release in the long-promised Libevent 2.0 series is finally out.  You can download Libevent 2.0.2-alpha from:<br />
<br />
  <a href="http://monkey.org/~provos/libevent-2.0.2-alpha.tar.gz">http://monkey.org/~provos/libevent-2.0.2-alpha.tar.gz</a><br />
<br />
This is an alpha release.  Libevent 2.0 is not finished.  There will be bugs, and we make no promises about the stability of any APIs introduced in the 2.0.x-alpha releases.  When you find bugs, please let us know.<br />
<br />
Libevent 2.0 is intended to be backward compatible with the Libevent 1.4 APIs[*].  Any program that worked with Libevent 1.4 should still work with Libevent 2.0, unless we screwed up.  Please test your programs when you have a chance, so that if we <u>did</u> screw up, we can notice soon.<br />
[*] Unless you were messing around with the internals of internal structures.<br />
<br />
This release adds many new features to the previous alpha release, and fixes many bugs.  See the ChangeLog for full details.  Highlights include:<br />
<ul><li>evdns is now threadsafe, with locking support</li><li>There's an evconnlistener type that you can use to abstract cross-platform differences in accepting connections.</li><li>The evbuffer interface (and therefore bufferevents) now supports zero-copy much better.</li><li>About a zillion fixes for tricky bugs in the new Libevent 2.0.1-alpha code.</li></ul><br />
Special thanks to everybody who helped find bugs and improve the code, especially James Mansion, Zack Weinberg, and Joachim Bauch. 
    <div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/NielsProvos?a=zja-1LvBcuI:Birzxd0TW6A:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/NielsProvos?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/NielsProvos?a=zja-1LvBcuI:Birzxd0TW6A:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/NielsProvos?i=zja-1LvBcuI:Birzxd0TW6A:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/NielsProvos?a=zja-1LvBcuI:Birzxd0TW6A:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/NielsProvos?i=zja-1LvBcuI:Birzxd0TW6A:F7zBnMyn0Lo" border="0"></img></a>
</div>]]></content:encoded>

    <pubDate>Tue, 28 Jul 2009 21:17:43 -0700</pubDate>
    <guid isPermaLink="false">http://www.provos.org/index.php?/archives/72-guid.html</guid>
    <category>libevent</category>
<category>release</category>

<feedburner:origLink>http://www.provos.org/index.php?/archives/72-New-Libevent-Releases.html</feedburner:origLink></item>
<item>
    <title>Aikido in Hamburg</title>
    <link>http://feedproxy.google.com/~r/NielsProvos/~3/mneFOLMaNtY/index.php</link>
            <category>News</category>
    
    <comments>http://www.provos.org/index.php?/archives/71-Aikido-in-Hamburg.html#comments</comments>
    <wfw:comment>http://www.provos.org/wfwcomment.php?cid=71</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.provos.org/rss.php?version=2.0&amp;type=comments&amp;cid=71</wfw:commentRss>
    

    <author>nospam@example.com (Niels Provos)</author>
    <content:encoded><![CDATA[
    Yesterday, I managed to practice <a href="http://www.aikido-schule-charlottenstrasse.de/">Aikido in Hamburg</a> for the first time in almost twelve years.  The dojo at Charlottenstraße was beautiful with windows to the outside and plenty of light.   The training was interesting and very enjoyable.  I even managed to practice with a few folks from university times.  Next week, it's back to the US and Aikido practice in <a href="http://aikidomv.com/">Mountain View</a>. 
    <div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/NielsProvos?a=mneFOLMaNtY:z_zMGZ-iUnw:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/NielsProvos?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/NielsProvos?a=mneFOLMaNtY:z_zMGZ-iUnw:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/NielsProvos?i=mneFOLMaNtY:z_zMGZ-iUnw:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/NielsProvos?a=mneFOLMaNtY:z_zMGZ-iUnw:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/NielsProvos?i=mneFOLMaNtY:z_zMGZ-iUnw:F7zBnMyn0Lo" border="0"></img></a>
</div>]]></content:encoded>

    <pubDate>Thu, 16 Jul 2009 02:53:43 -0700</pubDate>
    <guid isPermaLink="false">http://www.provos.org/index.php?/archives/71-guid.html</guid>
    <category>aikido</category>

<feedburner:origLink>http://www.provos.org/index.php?/archives/71-Aikido-in-Hamburg.html</feedburner:origLink></item>
<item>
    <title>DirectShow Vulnerability Exploited Everywhere</title>
    <link>http://feedproxy.google.com/~r/NielsProvos/~3/gonhsU-PfBA/index.php</link>
            <category>Malware</category>
            <category>Security</category>
            <category>SpyBye</category>
    
    <comments>http://www.provos.org/index.php?/archives/70-DirectShow-Vulnerability-Exploited-Everywhere.html#comments</comments>
    <wfw:comment>http://www.provos.org/wfwcomment.php?cid=70</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.provos.org/rss.php?version=2.0&amp;type=comments&amp;cid=70</wfw:commentRss>
    

    <author>nospam@example.com (Niels Provos)</author>
    <content:encoded><![CDATA[
    The <a href="http://secunia.com/advisories/35683/">DirectShow</a> <a href="http://www.symantec.com/connect/blogs/directshow-exploit-wild">vulnerabilities</a> are being exploited all over the place now.  Unfortunately, the <a href="http://www.computerworld.com/s/article/9135210/Hackers_exploit_second_DirectShow_zero_day_using_thousands_of_hijacked_sites">second vulnerability</a> in DirectShow is still unpatched and exploit sites seem to be jumping on this.  There is even some evidence that it's possible to <a href="http://www.viruslist.com/en/weblog?weblogid=208187760">successfully exploit</a> the vulnerability without even using JavaScript.   New <a href="http://isc.sans.org/diary.html?storyid=6739">exploit domains</a> are popping after <a href="http://google.com/safebrowsing/diagnostic?site=ch.ma/">every day</a>.  DirectShow now seems to be what Flash and PDF were earlier in the year. 
    <div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/NielsProvos?a=gonhsU-PfBA:EPhG5eGxTMM:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/NielsProvos?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/NielsProvos?a=gonhsU-PfBA:EPhG5eGxTMM:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/NielsProvos?i=gonhsU-PfBA:EPhG5eGxTMM:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/NielsProvos?a=gonhsU-PfBA:EPhG5eGxTMM:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/NielsProvos?i=gonhsU-PfBA:EPhG5eGxTMM:F7zBnMyn0Lo" border="0"></img></a>
</div>]]></content:encoded>

    <pubDate>Sat, 11 Jul 2009 09:38:16 -0700</pubDate>
    <guid isPermaLink="false">http://www.provos.org/index.php?/archives/70-guid.html</guid>
    <category>exploit</category>
<category>malware</category>
<category>security</category>

<feedburner:origLink>http://www.provos.org/index.php?/archives/70-DirectShow-Vulnerability-Exploited-Everywhere.html</feedburner:origLink></item>
<item>
    <title>Finn (1999 - 2009)</title>
    <link>http://feedproxy.google.com/~r/NielsProvos/~3/bKhMIr2YWX4/index.php</link>
            <category>News</category>
    
    <comments>http://www.provos.org/index.php?/archives/69-Finn-1999-2009.html#comments</comments>
    <wfw:comment>http://www.provos.org/wfwcomment.php?cid=69</wfw:comment>

    <slash:comments>3</slash:comments>
    <wfw:commentRss>http://www.provos.org/rss.php?version=2.0&amp;type=comments&amp;cid=69</wfw:commentRss>
    

    <author>nospam@example.com (Niels Provos)</author>
    <content:encoded><![CDATA[
    <a href="http://www.flickr.com/photos/nielsprovos/3687641811/" title="Finn (1999 - 2009) by provos@monkey, on Flickr"><img src="http://farm4.static.flickr.com/3588/3687641811_793c04058f.jpg" width="333" height="500" alt="Finn (1999 - 2009)" /></a> 
    <div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/NielsProvos?a=bKhMIr2YWX4:JBdIZlUbBKk:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/NielsProvos?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/NielsProvos?a=bKhMIr2YWX4:JBdIZlUbBKk:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/NielsProvos?i=bKhMIr2YWX4:JBdIZlUbBKk:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/NielsProvos?a=bKhMIr2YWX4:JBdIZlUbBKk:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/NielsProvos?i=bKhMIr2YWX4:JBdIZlUbBKk:F7zBnMyn0Lo" border="0"></img></a>
</div>]]></content:encoded>

    <pubDate>Sat, 04 Jul 2009 20:04:44 -0700</pubDate>
    <guid isPermaLink="false">http://www.provos.org/index.php?/archives/69-guid.html</guid>
    
<feedburner:origLink>http://www.provos.org/index.php?/archives/69-Finn-1999-2009.html</feedburner:origLink></item>
<item>
    <title>Testing the Zowada Forced-Air Manifold</title>
    <link>http://feedproxy.google.com/~r/NielsProvos/~3/d2a9yqHHbAY/index.php</link>
            <category>Hacking</category>
    
    <comments>http://www.provos.org/index.php?/archives/68-Testing-the-Zowada-Forced-Air-Manifold.html#comments</comments>
    <wfw:comment>http://www.provos.org/wfwcomment.php?cid=68</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.provos.org/rss.php?version=2.0&amp;type=comments&amp;cid=68</wfw:commentRss>
    

    <author>nospam@example.com (Niels Provos)</author>
    <content:encoded><![CDATA[
    I had time to forge down the 2in pipe for the nozzle today which completed everything needed for the burner.   Here is a video of the first test run.  Propane and air can be mixed separately via the gate valves which should allow precise control over the atmosphere in the forge.<br />
<object width="480" height="385"><param name="movie" value="http://www.youtube.com/v/dGx1iWHcU3E&hl=en&fs=1&rel=0&color1=0x006699&color2=0x54abd6"></param><param name="allowFullScreen" value="true"></param><param name="allowscriptaccess" value="always"></param><embed src="http://www.youtube.com/v/dGx1iWHcU3E&hl=en&fs=1&rel=0&color1=0x006699&color2=0x54abd6" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="480" height="385"></embed></object> 
    <div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/NielsProvos?a=d2a9yqHHbAY:D4Gjtku6BGs:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/NielsProvos?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/NielsProvos?a=d2a9yqHHbAY:D4Gjtku6BGs:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/NielsProvos?i=d2a9yqHHbAY:D4Gjtku6BGs:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/NielsProvos?a=d2a9yqHHbAY:D4Gjtku6BGs:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/NielsProvos?i=d2a9yqHHbAY:D4Gjtku6BGs:F7zBnMyn0Lo" border="0"></img></a>
</div>]]></content:encoded>

    <pubDate>Fri, 03 Jul 2009 21:21:48 -0700</pubDate>
    <guid isPermaLink="false">http://www.provos.org/index.php?/archives/68-guid.html</guid>
    <category>blacksmithing</category>
<category>forge</category>

<feedburner:origLink>http://www.provos.org/index.php?/archives/68-Testing-the-Zowada-Forced-Air-Manifold.html</feedburner:origLink></item>
<item>
    <title>The Village Blacksmith</title>
    <link>http://feedproxy.google.com/~r/NielsProvos/~3/BxhJia7QBxE/index.php</link>
            <category>Hacking</category>
    
    <comments>http://www.provos.org/index.php?/archives/67-The-Village-Blacksmith.html#comments</comments>
    <wfw:comment>http://www.provos.org/wfwcomment.php?cid=67</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.provos.org/rss.php?version=2.0&amp;type=comments&amp;cid=67</wfw:commentRss>
    

    <author>nospam@example.com (Niels Provos)</author>
    <content:encoded><![CDATA[
    The landlord visited today while I was working on some bolt jaw tongs.   When he saw me blacksmithing, he told me that he used to turn the crank blower for a blacksmith when he was a boy and recited the following poem:<br />
<blockquote>Under a spreading chestnut tree<br />
The village smithy stands;<br />
The smith, a mighty man is he,<br />
With large and sinewy hands;<br />
And the muscles of his brawny arms<br />
Are strong as iron bands.<br />
  <br />
His hair is crisp, and black, and long,<br />
His face is like the tan;<br />
His brow is wet with honest sweat,<br />
He earns whate'er he can,<br />
And looks the whole world in the face,<br />
For he owes not any man.</blockquote> <br /><a href="http://www.provos.org/index.php?/archives/67-The-Village-Blacksmith.html#extended">Continue reading "The Village Blacksmith"</a>
    <div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/NielsProvos?a=BxhJia7QBxE:VIk4OdAWD70:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/NielsProvos?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/NielsProvos?a=BxhJia7QBxE:VIk4OdAWD70:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/NielsProvos?i=BxhJia7QBxE:VIk4OdAWD70:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/NielsProvos?a=BxhJia7QBxE:VIk4OdAWD70:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/NielsProvos?i=BxhJia7QBxE:VIk4OdAWD70:F7zBnMyn0Lo" border="0"></img></a>
</div>]]></content:encoded>

    <pubDate>Thu, 02 Jul 2009 13:49:12 -0700</pubDate>
    <guid isPermaLink="false">http://www.provos.org/index.php?/archives/67-guid.html</guid>
    
<feedburner:origLink>http://www.provos.org/index.php?/archives/67-The-Village-Blacksmith.html</feedburner:origLink></item>
<item>
    <title>Cybercrime 2.0: When the Cloud Turns Dark</title>
    <link>http://feedproxy.google.com/~r/NielsProvos/~3/IBfRi5cdr3I/index.php</link>
            <category>Malware</category>
            <category>Security</category>
            <category>SpyBye</category>
    
    <comments>http://www.provos.org/index.php?/archives/66-Cybercrime-2.0-When-the-Cloud-Turns-Dark.html#comments</comments>
    <wfw:comment>http://www.provos.org/wfwcomment.php?cid=66</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.provos.org/rss.php?version=2.0&amp;type=comments&amp;cid=66</wfw:commentRss>
    

    <author>nospam@example.com (Niels Provos)</author>
    <content:encoded><![CDATA[
    We recently published an article on <a href="http://queue.acm.org/detail.cfm?id=1517412">web-based malware</a> in ACM's Queue Magazine.  It provides a short overview of some of the challenges with detecting malicious web sites such as social engineering and examples of techniques for compromising web sites, e.g. htaccess redirection on Apache, etc.  This is the article on which my recent ISSNet talk was based. 
    <div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/NielsProvos?a=IBfRi5cdr3I:kQF78L2si5k:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/NielsProvos?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/NielsProvos?a=IBfRi5cdr3I:kQF78L2si5k:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/NielsProvos?i=IBfRi5cdr3I:kQF78L2si5k:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/NielsProvos?a=IBfRi5cdr3I:kQF78L2si5k:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/NielsProvos?i=IBfRi5cdr3I:kQF78L2si5k:F7zBnMyn0Lo" border="0"></img></a>
</div>]]></content:encoded>

    <pubDate>Wed, 01 Jul 2009 08:19:59 -0700</pubDate>
    <guid isPermaLink="false">http://www.provos.org/index.php?/archives/66-guid.html</guid>
    <category>exploit</category>
<category>malware</category>
<category>security</category>

<feedburner:origLink>http://www.provos.org/index.php?/archives/66-Cybercrime-2.0-When-the-Cloud-Turns-Dark.html</feedburner:origLink></item>
<item>
    <title>Making A Monkey Tool</title>
    <link>http://feedproxy.google.com/~r/NielsProvos/~3/1U7TpjqF7S4/index.php</link>
            <category>Hacking</category>
    
    <comments>http://www.provos.org/index.php?/archives/65-Making-A-Monkey-Tool.html#comments</comments>
    <wfw:comment>http://www.provos.org/wfwcomment.php?cid=65</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.provos.org/rss.php?version=2.0&amp;type=comments&amp;cid=65</wfw:commentRss>
    

    <author>nospam@example.com (Niels Provos)</author>
    <content:encoded><![CDATA[
    <a class='serendipity_image_link' href='http://www.provos.org/uploads/MonkeyTool.jpg'><!-- s9ymdb:1 --><img class="serendipity_image_left" width="300"  style="float: left; border: 0px; padding-left: 5px; padding-right: 5px;" src="http://www.provos.org/uploads/MonkeyTool.jpg" alt="" /></a>I learned how to make a monkey tool today.   Monkey tools can be used for dressing tenons.   The basic procedure is as follows. <br />
<em>Take 1in square stock and chamfer the edges.   Take a slot punch and move it about an 1in from the corner - this is the hammer end.   Line the slot punch up very carefully, so that its straight and divides the stock in the middle.   Hit it a couple times to get a registration.  Now, get the stock nice and hot, align the slot punch with the registration, hit it hard three times, cool the slot punch in water, rotate it by 180 degrees and repeat.   At some point, the slot punch is almost through, flip the stock over and use the slot punch to punch out the remaining piece of metal.  Now, use a drift to open up the hole to the desired size.   Start the drift from the other side of the slot.   Doing this over the hardy hole is a good idea.   With the slot still inserted, dress up the faces.   Then chamfer the corners.  Cut off the other side for the length of the tenon and drill a hole of the right size.</em><br />
That's it.   Out of the four holes I drifted only two came out sort of in the middle <img src="http://www.provos.org/templates/default/img/emoticons/smile.png" alt=":-)" style="display: inline; vertical-align: bottom;" class="emoticon" /> 
    <div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/NielsProvos?a=1U7TpjqF7S4:AID6I_6_PoA:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/NielsProvos?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/NielsProvos?a=1U7TpjqF7S4:AID6I_6_PoA:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/NielsProvos?i=1U7TpjqF7S4:AID6I_6_PoA:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/NielsProvos?a=1U7TpjqF7S4:AID6I_6_PoA:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/NielsProvos?i=1U7TpjqF7S4:AID6I_6_PoA:F7zBnMyn0Lo" border="0"></img></a>
</div>]]></content:encoded>

    <pubDate>Sat, 27 Jun 2009 14:23:45 -0700</pubDate>
    <guid isPermaLink="false">http://www.provos.org/index.php?/archives/65-guid.html</guid>
    <category>blacksmithing</category>

<feedburner:origLink>http://www.provos.org/index.php?/archives/65-Making-A-Monkey-Tool.html</feedburner:origLink></item>
<item>
    <title>Building a forge</title>
    <link>http://feedproxy.google.com/~r/NielsProvos/~3/YhxdEw9Wofk/index.php</link>
            <category>Hacking</category>
            <category>News</category>
            <category>SpyBye</category>
            <category>Systrace</category>
    
    <comments>http://www.provos.org/index.php?/archives/64-Building-a-forge.html#comments</comments>
    <wfw:comment>http://www.provos.org/wfwcomment.php?cid=64</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.provos.org/rss.php?version=2.0&amp;type=comments&amp;cid=64</wfw:commentRss>
    

    <author>nospam@example.com (Niels Provos)</author>
    <content:encoded><![CDATA[
    To get better control over the atmosphere in the forge, I have decided to build a blown gas forge based on a <a href="http://www.tzknives.com/gasforges.html">design</a> by Tim Zowada.  The basic structure is provided by a 10 gallon compressed air tank I picked up from Lowes.  Using Tim's <a href="http://www.tzknives.com/manifold.html">forced-air manifold,</a> the forge should easily get up to welding temperature (2300F).<br />
<br />
Jon who runs the <a href="http://www.temperchi.com/">TemperChi Glass Art Studio</a> is helping with building this thing and already has some cerawool for lining the inside.   The Cerawool is going to get covered with a 1/4in layer of Satanite and then with an ITC-100 coating.   The forge floor will be made from <a href="http://elliscustomknifeworks.hightemptools.com/refractorycoatings.html">Bubble Alumina refractory</a> which has a heat rating of up 3300F and is supposed to be very resistant to flux.   The inside diameter of the forge will be 8 inches and the length about 12 inches.<br />
<br />
If you are interested in <a href="http://www.temperchi.com/">making glass beads</a>, you can learn that at the shop, too, as well as welding <img src="http://www.provos.org/templates/default/img/emoticons/smile.png" alt=":-)" style="display: inline; vertical-align: bottom;" class="emoticon" /> 
    <div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/NielsProvos?a=YhxdEw9Wofk:hJTfBtav9ss:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/NielsProvos?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/NielsProvos?a=YhxdEw9Wofk:hJTfBtav9ss:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/NielsProvos?i=YhxdEw9Wofk:hJTfBtav9ss:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/NielsProvos?a=YhxdEw9Wofk:hJTfBtav9ss:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/NielsProvos?i=YhxdEw9Wofk:hJTfBtav9ss:F7zBnMyn0Lo" border="0"></img></a>
</div>]]></content:encoded>

    <pubDate>Mon, 22 Jun 2009 23:45:42 -0700</pubDate>
    <guid isPermaLink="false">http://www.provos.org/index.php?/archives/64-guid.html</guid>
    <category>bladesmithing</category>
<category>forge</category>

<feedburner:origLink>http://www.provos.org/index.php?/archives/64-Building-a-forge.html</feedburner:origLink></item>
<item>
    <title>Top 10 Malware Sites</title>
    <link>http://feedproxy.google.com/~r/NielsProvos/~3/OoZDCuoCFnE/index.php</link>
            <category>Malware</category>
            <category>News</category>
            <category>Security</category>
            <category>SpyBye</category>
    
    <comments>http://www.provos.org/index.php?/archives/63-Top-10-Malware-Sites.html#comments</comments>
    <wfw:comment>http://www.provos.org/wfwcomment.php?cid=63</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.provos.org/rss.php?version=2.0&amp;type=comments&amp;cid=63</wfw:commentRss>
    

    <author>nospam@example.com (Niels Provos)</author>
    <content:encoded><![CDATA[
    A list of the <a href="http://googleonlinesecurity.blogspot.com/2009/06/top-10-malware-sites.html">top-10 malware</a> sites found by Google's infrastructure over the last two months is available at the <a href="http://googleonlinesecurity.blogspot.com/">Google Online Security Blog</a>.  Gumblar and Martuz are among them as well as <a href="http://google.com/safebrowsing/diagnostic?site=googleanalytlcs.net">googleanalytlcs.net</a>.   There certainly have been lots of compromised web servers recently. 
    <div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/NielsProvos?a=OoZDCuoCFnE:m4UMNfxzQQ0:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/NielsProvos?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/NielsProvos?a=OoZDCuoCFnE:m4UMNfxzQQ0:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/NielsProvos?i=OoZDCuoCFnE:m4UMNfxzQQ0:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/NielsProvos?a=OoZDCuoCFnE:m4UMNfxzQQ0:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/NielsProvos?i=OoZDCuoCFnE:m4UMNfxzQQ0:F7zBnMyn0Lo" border="0"></img></a>
</div>]]></content:encoded>

    <pubDate>Sat, 06 Jun 2009 10:03:02 -0700</pubDate>
    <guid isPermaLink="false">http://www.provos.org/index.php?/archives/63-guid.html</guid>
    <category>malware</category>

<feedburner:origLink>http://www.provos.org/index.php?/archives/63-Top-10-Malware-Sites.html</feedburner:origLink></item>
<item>
    <title>LEET'09: Large Scale Exploits and Emergent Threats</title>
    <link>http://feedproxy.google.com/~r/NielsProvos/~3/wWl0VbYUWws/index.php</link>
            <category>Malware</category>
            <category>News</category>
            <category>Security</category>
    
    <comments>http://www.provos.org/index.php?/archives/62-LEET09-Large-Scale-Exploits-and-Emergent-Threats.html#comments</comments>
    <wfw:comment>http://www.provos.org/wfwcomment.php?cid=62</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.provos.org/rss.php?version=2.0&amp;type=comments&amp;cid=62</wfw:commentRss>
    

    <author>nospam@example.com (Niels Provos)</author>
    <content:encoded><![CDATA[
    The 2nd USENIX LEET workshop is going to take place on April 21st in Boston next week.   The <a href=" http://www.usenix.org/events/leet09/tech/tech.html">workshop program</a> looks really interesting.  There are a number of really interesting talks; here are just a few:<br />
<br />
<ul><li>Spamcraft: An Inside Look At Spam Campaign Orchestration</li><li>A Foray into Conficker's Logic and Rendezvous Points</li><li>A View on Current Malware Behaviors</li></ul><br />
<br />
Last year's workshop was a blast and I expect that next week is going to be lots of fun, too.   It is still possible to <a href="http://www.usenix.org/events/leet09/registration/">register on-site</a> for the workshop. 
    <div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/NielsProvos?a=wWl0VbYUWws:bnruiFHgmu0:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/NielsProvos?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/NielsProvos?a=wWl0VbYUWws:bnruiFHgmu0:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/NielsProvos?i=wWl0VbYUWws:bnruiFHgmu0:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/NielsProvos?a=wWl0VbYUWws:bnruiFHgmu0:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/NielsProvos?i=wWl0VbYUWws:bnruiFHgmu0:F7zBnMyn0Lo" border="0"></img></a>
</div>]]></content:encoded>

    <pubDate>Tue, 14 Apr 2009 17:25:08 -0700</pubDate>
    <guid isPermaLink="false">http://www.provos.org/index.php?/archives/62-guid.html</guid>
    <category>security</category>
<category>usenix</category>

<feedburner:origLink>http://www.provos.org/index.php?/archives/62-LEET09-Large-Scale-Exploits-and-Emergent-Threats.html</feedburner:origLink></item>

</channel>
</rss>
